logo

Critical default credential in Kubernetes Image Builder allows SSH root access

ID: 47f053ec-af3d-5321-b1f5-9c748edd41c8

STIX ID: report--47f053ec-af3d-5321-b1f5-9c748edd41c8

Feed Name: The Register (Security)

Threat Score
75/100

Date Published: 2024-10-16

Date Updated: 2026-04-26

Author: Jessica Lyons

...
...

A critical vulnerability in Kubernetes Image Builder (v0.1.37 and earlier) can leave default credentials in VM images, enabling remote root SSH access; Proxmox-built images are rated CVSS 9.8 (CVE-2024-9486) while other providers have a CVSS 6.3 variant (CVE-2024-9594). Users should upgrade to Image Builder v0.1.38 or later (which randomizes and disables the builder account) or disable the builder account and redeploy affected images to mitigate risk.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.